URLhaus Database

You are currently viewing the URLhaus database entry for https://www.gasmar.com.br/Facebook/F4yHC/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123215
URL: https://www.gasmar.com.br/Facebook/F4yHC/?i=1
URL Status:Offline
Host: www.gasmar.com.br
Date added:2022-03-30 20:23:08 UTC
Last online:2022-04-01 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 20:24:06 UTC to abuse{at}locaweb[dot]com[dot]br)
Takedown time:1 day, 18 hours, 53 minutes Poor (down since 2022-04-01 15:17:47 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01BM-1313209.xlsmxlsm 8090d0b6d046091604553a331f669273c32d27943faae06a33b6ffda57479dafVirustotal results 45.16%Heodo
2022-04-01YZ-956103664461.xlsmxlsm 60833a18e14a8b4eb21cec280bdac63e8a03eeda78c1c5e0e641624b72000be8n/a Heodo
2022-04-01TNJ-152305024.xlsmxlsm 3ae76b8b56720b9de3d4d679e5e5b70232ade7e9461635465d025c0a9b861ffdn/a Heodo
2022-04-01OSP-680496455.xlsmxlsm 0c4ef4b03683b5c927b33e01bc6c59d7e6af72175bf42280dbe042b628d56eaan/a Heodo
2022-04-01WEO-957132589.xlsmxlsm a952453aee7b5d358259b92750c559cdf583f54496aa8a8b81a5aa27d2b18dfaVirustotal results 39.29% Heodo
2022-04-01AWB-483784604868.xlsmxlsm 989afb22d889ef10aefc7185c5a8d051fa3dd6c0f2a6a811c1a89498e293b615n/a Heodo
2022-04-01CQP-47217539024.xlsmxlsm cb8b7ab96bb04ee8d5961b315979e71335c048e9eb3a3bfac2f273731544f0fbn/a Heodo
2022-04-01PNE-6098274997498.xlsmxlsm fd9c7b2de5f9a936c9a16ba8ae8e5215dc92021e435a8285fb36ccadd20e871fVirustotal results 38.98% Heodo
2022-04-01VD-800526794.xlsmxlsm bba184efb454972191ec837362eddc4ef35f60b616033ef54cbd77d1a70f8f3fn/a Heodo
2022-04-01IUU-4878442052858.xlsmxlsm f3c06e72e6b0cddb3d66545d59bef1288458f9c106ede60b0507f095971e7067n/a Heodo
2022-04-01BE-290767564.xlsmxlsm bae96f9a32122e9edb5b64e650dad2249b1dae898540a74641fdd9a4fe860edfn/a Heodo
2022-04-01TRD-20932127.xlsmxlsm 41169580013c884c968404a805765bab464032270676b792b39ae2b521a64dfeVirustotal results 40.32% Heodo
2022-04-01BEI-470430236193.xlsmxlsm a4c90f279a6b95cfa27debaf12cd09e6dd57fb1eb87803667a8b0527c7fc27ceVirustotal results 43.55% Heodo
2022-04-01GA-667102219363.xlsmxlsm 9ca7e881cd1e46ca3a73efbad250390fbb3fbc92c6d90d0f25c6a218055f323bn/a Heodo
2022-04-01ZKP-2153929289937.xlsmxlsm a88019c1e8c87847f6816dba7e30475a768da155993e7fa208063dffd2422811n/a Heodo
2022-04-01NO-2192802474979.xlsmxlsm 4967f52b4eec67dedea5ef764a47c545db43f04f5b0f1355dfa16c8b8bc6e1e8n/a Heodo
2022-04-01GF-4573758654917.xlsmxlsm 23c128385a0702939e1b4bd33875e38dc27cec42b5561f54859abaa962d2930dn/a Heodo
2022-04-01ML-01109019043615.xlsmxlsm d17e95fb87ae8a3011b050d5c9c089f3bc06fddd1a61feb4812380e96b541e73Virustotal results 46.77% Heodo
2022-03-31ERU-0511009500502.xlsmxlsm 5fb54e96fe17c395fa69dc06933558b083ae9cfb1391218f12c539c2645a8311n/a Heodo
2022-03-31PTK-6381689808083.xlsmxlsm 5144b4176d2f9e56ad483565884642378be09039de1f2a353cb355c00dfa1894n/aHeodo
2022-03-31UJ-963207056790.xlsmxlsm 4e6c2dd2bb0183aa17caa2084632719d1b9d42cae3e0c96f6770b216822b8d01n/a Heodo
2022-03-31CWX-85133116936.xlsmxlsm 10281dd74601704b43cbce7093951762bfb6cc0402f747ba01250b2ebc438c27Virustotal results 35.48% Heodo
2022-03-31UHB-613946013424785.xlsmxlsm c201ae0ab0516a27d14400b4af28d4189bb2c6d8b589c4fadb025c26645f19bfVirustotal results 38.10% Heodo
2022-03-31XEI-9731419.xlsmxlsm 317b14af792a2e4b877fd65cd6dc1cdceaf3d9573dcc1cf673e5008d38f7b6caVirustotal results 35.59% Heodo
2022-03-31NRI-761236986015631.xlsmxlsm 0e92cfd04405b8b597562761080285f19807c04c48c7278fe7632271ded41c3dVirustotal results 40.00% Heodo
2022-03-31XOH-8486159212655.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31UJU-556028341.xlsmxlsm 9098c46a233798193c0587711f5a9be2a4aa97567db08504452748dde516053aVirustotal results 34.92% Heodo
2022-03-31UXN-2379177945.xlsmxlsm f88eb7101fdc0fe20190969ec3bb4651bf4f270d9a9636d6c1e1a84ae46a9cd6Virustotal results 37.10% Heodo
2022-03-31ZWA-3310998994.xlsmxlsm 30deb7a7086f74317285271a2e26e40dc43b461a1a77c77480ea742b02cbe51fVirustotal results 38.10% Heodo
2022-03-31PNN-9893047233195.xlsmxlsm f1a59459dc11d8edab701cdd7610dd6310993ddb1aa04ab43f8fc3536040700dn/a Heodo
2022-03-31MK-85264020565497.xlsmxlsm 02830d05c8978247bcf9d67de7de69472a79c9f8c2a34c6e19174da73f50f627n/a Heodo
2022-03-31ZZG-028878598.xlsmxlsm 162637428037d1f8f3bd675b122e5b830107b9ea7352c8c765e97a3afbce1231n/a Heodo
2022-03-31NPA-65608829283262.xlsmxlsm a1057f814e603d7b7ff7b711305cac0ef15e48b78499802d411424a19ee235f8Virustotal results 34.92% Heodo
2022-03-30ZU-939764008609.xlsmxlsm 60198b10fd3c8daeeb186be258cdf74b24c18a364638c8b6c6370e0bf4a005e5Virustotal results 33.87% Heodo
2022-03-30UPO-571940922896.xlsmxlsm 9da38d7964f16ed0c46e5a0ee55152196bf8368f5e2d2b08cbf8c24932ec490dn/a Heodo
2022-03-30XU-132153472.xlsxls a14fb7f51582ec1f9af65f4300ff4dde6a99d12bd2b08f70863ca16d508c72baVirustotal results 28.33% Heodo
2022-03-3096902628772697208.xlsxls 6edf2bbc238af34d4d9a013d6ae99ec1a1df41d15caa4bf4e90ec5fd50ac19eeVirustotal results 28.33%SilentBuilder